oss-sec mailing list archives
CVE-2026-77176: Kata-containers: insufficient validation of createcontainer mount and storage rules in genpolicy
From: Manuel Huber <manuelh () nvidia com>
Date: Thu, 20 Aug 2026 21:11:27 +0000
This vulnerability has been fixed in Kata Containers. The fix will be included in the upcoming 4.1.0 release, which is expected to be available shortly: genpolicy: don't match image pull storages to mounts <https://github.com/kata-containers/kata-containers/commit/fe8eeefcd0bec13c0 37ceb8f0889e48b75db17ab> . kata-containers/kata-containers@fe8eeef Description: A flaw was found in Kata Containers. In configurations utilizing genpolicy for Confidential Containers guest protection, a malicious host operator can exploit insufficient validation of CreateContainer mount and storage rules. This allows them to mount arbitrary container-rootfs paths over sensitive host locations or provision arbitrary content, potentially exposing confidential information or enabling the acceptance of attacker-controlled input. CVE: CVE-2026-77176 GHSA: GHSA-fmg6-v47x-52wr Original report: generated policy allows mounting attacker-chosen guest paths to specific locations <https://github.com/kata-containers/kata-containers/security/advisories/GHSA -fmg6-v47x-52wr> . Advisory . kata-containers/kata-containers --- Manuel Huber, on behalf of the Kata Containers Vulnerability Management Team
Attachment:
smime.p7s
Description:
Current thread:
- CVE-2026-77176: Kata-containers: insufficient validation of createcontainer mount and storage rules in genpolicy Manuel Huber (Aug 20)
